HoneyLabs
iAnonymous lookups: 10/min, 60/hr per source IP. Sign in (free) to lift the limit, run heavier queries, and get an API key for MCP / HTTP.

Filtered actors

query: port:83

47 unique IPs · 218 events · 9 countries · 19 ASNs

Activity · last 24h

2026-06-22: 146 events2026-06-23: 72 events

peak 146 on 2026-06-22

Top source networks · click to refine

Refine
Turn this query into a daily email digest or an IOC feed URL.Save as feed

Sample payloads

top distinct probes matching this query
ProtocolPortProbe / payloadHitsExample
HTTP83GET /SDK/webLanguage
UA: Mozilla/5.0
76 · 5 IPs93.123.72.183 →
HTTP83GET /
UA: Python/3.10 aiohttp/3.8.4
74 · 32 IPs80.82.77.202 →
HTTP83GET /favicon.ico
UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
20 · 12 IPs66.132.172.205 →
TPKT83TPKT / COTP (ISO-TSAP)03 00 00 13 0e e0 00 00 00 00 00 01 00 08 00 02 00 00 0012 · 2 IPs160.119.76.16 →
HTTP83TRACE / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.199 Safari/537.36 Accept-Encoding: gzip, deflate …85.61.209.92 →
HTTP83GET http://api.ipify.org/?format=json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
4 · 4 IPs65.49.1.28 →
TLS8350 52 49 20 2a 20 48 54 54 50 2f 32 2e 30 0d 0a 0d 0a 53 4d 0d 0a 0d 0a …(57 bytes)4 · 4 IPs66.132.172.205 →
-830a4 · 2 IPs3.130.168.2 →
-83MGLNDD_<HONEYPOT>_834 · 4 IPs20.65.194.160 →
HTTP83GET /.well-known/security.txt
UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
166.132.172.218 →
HTTP83CONNECT www.shadowserver.org:443 HTTP/1.1 Host: www.shadowserver.org User-Agent: Mozilla/5.0 (Windows NT 10.0.0; Win64; x64; ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0…164.62.156.191 →
HTTP83CONNECT www.shadowserver.org:443 HTTP/1.1 Host: www.shadowserver.org User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.0 Connection: Kee…164.62.156.215 →
IPCountryASNTop portsEvents
31.59.160.12🇦🇪AEunknown network8318
Showing top 50 by event count. Window is the last 24h. Add or remove filters by clicking any value on a per-IP report.